CVE-2026-2708
published 2026-04-23CVE-2026-2708: A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.32%
24.5th percentile
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2m77-r9w3-w44v: A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic
ghsa_unreviewed·2026-04-24
CVE-2026-2708 [LOW] CWE-444 GHSA-2m77-r9w3-w44v: A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.
VulDB
GNOME libsoup HTTP Request Content-Length request smuggling (EUVD-2026-25306 / Nessus ID 299615)
vuldb·2026-04-24·CVSS 3.7
CVE-2026-2708 [LOW] GNOME libsoup HTTP Request Content-Length request smuggling (EUVD-2026-25306 / Nessus ID 299615)
A vulnerability, which was classified as critical, was found in GNOME libsoup. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. Such manipulation of the argument Content-Length leads to http request smuggling.
This vulnerability is documented as CVE-2026-2708. The attack can be executed remotely. There is not any exploit available.
OSV
CVE-2026-2708: [libsoup: HTTP/1 request smuggling primitives accepted (CL
osv·2026-02-23
CVE-2026-2708 CVE-2026-2708: [libsoup: HTTP/1 request smuggling primitives accepted (CL
[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]
Red Hat
libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
vendor_redhat·2026-02-18·CVSS 3.7
CVE-2026-2708 [LOW] CWE-444 libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.
Statement: The practical impact is limited because SoupServer is a testing and development utility, not designed for production internet infrastructure. Exploitation requires a deployment topology where SoupServer is serving real traffic behind (or in front of) another HTTP server acting as a proxy — a scenario that contradict
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-2708 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-2708 [MEDIUM] CVE-2026-2708 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2708 :
Linux Debian vulnerability analysis and mitigation
[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]
Source : NVD
Published February 23, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsoup-devel
libsoup-lang
Sources
NVD
Debian 11, 14 No Fix Added at: Feb 20, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Feb 20, 2026
Echo No Fix Added at: Feb 20, 2026
Red Hat 6, 7, 8, 9, 10 Severity LOW No Fix Added at: Feb 20, 2026
Red Hat 7 Has Fix Added at: Feb 21, 2026
## Get a
Bugzilla
CVE-2026-2708 libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
bugzilla·2026-02-18·CVSS 5.3
CVE-2026-2708 [MEDIUM] CVE-2026-2708 libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
CVE-2026-2708 libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.
2026-04-23
Published